CVE-2018-2454: SAP Enterprise Financial Services

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Affected products

  • SAP Enterprise Financial Services: version 6.05 only; version 6.06 only; version 6.16 only; version 6.17 only; version 6.18 only; version 8.0 only

Published 2018-09-11. Last modified 2026-06-17.